<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: socketcluster</title><link>https://news.ycombinator.com/user?id=socketcluster</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 11 Sep 2026 13:10:25 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=socketcluster" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by socketcluster in "Resist "AI""]]></title><description><![CDATA[
<p>I'm an open source dev and I appreciate AI. I'm glad it exists and I have no problem with people being rewarded for their work on AI.<p>That said, I also think everyone who contributed content online deserves to be rewarded for their contribution, especially since OpenAI (which made the largest contribution) was a non-profit in the beginning. So there should be some kind of tax. Otherwise I agree, it's not ethical. It's not 'fair use' of copyrights.</p>
]]></description><pubDate>Fri, 11 Sep 2026 12:06:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49657037</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49657037</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49657037</guid></item><item><title><![CDATA[New comment by socketcluster in "OpenAI Agents API"]]></title><description><![CDATA[
<p>Though I'm not surprised by this offering, I feel like I need some time to absorb it. It feels like the stepping stone to the next big thing.<p>It's going to destroy a lot of startups which were monetizing this exact idea. But clearly it's a low-hanging fruit so it makes sense that OpenAI would do it.</p>
]]></description><pubDate>Fri, 11 Sep 2026 07:50:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49654900</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49654900</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49654900</guid></item><item><title><![CDATA[New comment by socketcluster in "My business partner sent a 5K vibe-coded PR that he didn't even test"]]></title><description><![CDATA[
<p>>> I was banking on the opportunities it will create but nah<p>Seems we're on the same wavelength because I had the exact same thought about this.<p>But actually, I'm probably not so fussy. I wouldn't mind cleaning up the mess if I'm paid hourly... But now my concern is: What if they want me to clean up the mess but demand that I do it in a particular way which makes it impossible?<p>I'm already seeing signs of this. This was already kind of the case in my last job; I had to fix things and implement new features but we had to keep the same clunky, over-engineered architecture. My current job doesn't have the same degree of architectural legacy baggage but there is a lot of bureaucracy to deal with instead, which is itself restrictive.</p>
]]></description><pubDate>Tue, 08 Sep 2026 10:39:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49608433</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49608433</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49608433</guid></item><item><title><![CDATA[New comment by socketcluster in "My business partner sent a 5K vibe-coded PR that he didn't even test"]]></title><description><![CDATA[
<p>This is literally the recipe for the coming software apocalypse.<p>Just watch the software engineers who say "Let's be careful" lose their jobs and get replaced by non-technical vibe-coders churning out 10K lines of dirty insecure, unmaintainable code per day... Ticking time bomb.<p>I swear, good engineers are going to move to North Korea to monetize because of the amount and size of 'opportunities' this will create.<p>It seems so far-fetched but that's the direction it seems to be heading.</p>
]]></description><pubDate>Tue, 08 Sep 2026 08:36:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49607391</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49607391</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49607391</guid></item><item><title><![CDATA[New comment by socketcluster in "Ask HN: How do you manage skills files?"]]></title><description><![CDATA[
<p>I make skills to allow AI to integrate with my platform; it's documentation with cURL commands. It can interact with every aspect of my platform via HTTP and access its full capabilities. I can tweak its token permissions as I like and revoke access if necessary.</p>
]]></description><pubDate>Mon, 07 Sep 2026 15:27:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49599484</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49599484</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49599484</guid></item><item><title><![CDATA[New comment by socketcluster in "Coding expertise is going to collapse from AI reliance"]]></title><description><![CDATA[
<p>My experience is that AI has significantly boosted the value of a quality code-base. A good codebase essentially codes itself.<p>There are project I've built from scratch that I would feel confident to hand off to a bunch of non-technical vibe coders and I know they would be productive and the product would likely be secure; because the existing codebase already exhibits all the patterns and principles that are required for that kind of project.<p>It would probably slowly degrade over time if a lot of vibe-coded logic is added on top but I think they could get very far feature-wise whilst keeping the software reliable.<p>But even though the value of such codebase has increased, people haven't adapted to this new reality. People are generally not good at telling what is good code. Because we don't actually have consensus on a definition. My definition is that good code is code that is easy to extend and maintain.<p>If implementing a feature requires a huge amount of tokens, then there's a good chance the codebase is not great.<p>I've worked on a codebase where a small feature requires might require 3k tokens, but on a different codebase, a feature of similar complexity would require 30k tokens minimum... And it's not about the size of the project; it's more about how the logic is divided and the architecture. And importantly; it's not a one-off; it's a clear observable, repeatable pattern.</p>
]]></description><pubDate>Mon, 24 Aug 2026 23:34:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49427275</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49427275</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49427275</guid></item><item><title><![CDATA[New comment by socketcluster in "PostgreSQL for Everything"]]></title><description><![CDATA[
<p>This article seems like a reaction to DuckDB's surge in popularity. Having multiple DB engines to choose from is good and it often doesn't matter which one you use. One could make the same argument about DuckDB. Many database engines are multi-purpose. Though of course there are specific use cases where a different DB may be more appropriate...<p>Anyway databases nowadays are a commodity. A sticky commodity but nonetheless they are replaceable; increasingly so in the age of AI where data migrations are easier than ever.</p>
]]></description><pubDate>Thu, 20 Aug 2026 02:32:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49369764</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49369764</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49369764</guid></item><item><title><![CDATA[New comment by socketcluster in "Extensible Software in the age of LLMs"]]></title><description><![CDATA[
<p>Sandboxed execution is definitely one aspect... But IMO, this is still not secure enough for vibe coders. They will want to have data-driven apps to share among small groups of people, then the security of the sandbox doesn't matter if they expose some external endpoints and if the access control logic which guards data is flawed.<p>Even if each user gets their own sandbox, they will still want to configure different access rules for different kinds of data which they host.<p>That said the idea that each user could control and host their own data is interesting and could work. I imagine you could have apps which link data from many different user sandboxes via remote foreign keys.<p>You could have a centralized data schema controlled by the application owner but the data itself would be held/scattered across a large number of sandboxes.</p>
]]></description><pubDate>Wed, 19 Aug 2026 23:30:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=49368548</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49368548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49368548</guid></item><item><title><![CDATA[New comment by socketcluster in "A joke domain purchase turned in geopolitical warfare"]]></title><description><![CDATA[
<p>I enjoyed reading this. It has a "butterfly effect" kind of vibe how such a random trivial-sounding pursuit can lead to something consequential. It's also mind-opening to realize how many strange human activities are happening in the background.</p>
]]></description><pubDate>Wed, 19 Aug 2026 22:25:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49367969</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49367969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49367969</guid></item><item><title><![CDATA[New comment by socketcluster in "HTML over WebSockets: real-time SPAs with barely any JavaScript"]]></title><description><![CDATA[
<p>Reading this is especially interesting to me because it's what I've been working towards for the last 14 years or so. Though like this group, it also came together for me piece by piece.<p>I got interested in this specific idea back in the early days of Firebase I saw someone built a realtime HTML component with PolymerJS called 'collection' and I became consumed by the idea of fully generic realtime self-updating components. My approach is a bit different than OP or that of HTMX though; it's JSON over the wire, not HTML.<p>I've built a full implementation in Node.js with a set of declarative frontend components.<p><a href="https://github.com/Saasufy/saasufy-components?tab=readme-ov-file#saasufy-components" rel="nofollow">https://github.com/Saasufy/saasufy-components?tab=readme-ov-...</a><p>And <a href="https://saasufy.com/" rel="nofollow">https://saasufy.com/</a><p>I'm thinking to make open source.<p>It's nice to see major frameworks coming to a similar conclusion.</p>
]]></description><pubDate>Wed, 12 Aug 2026 21:41:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49278959</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49278959</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49278959</guid></item><item><title><![CDATA[New comment by socketcluster in "Go is an ideal language for AI-assisted software engineering"]]></title><description><![CDATA[
<p>Yes. Vanilla JS is the best. You don't need TypeScript, Claude never makes type errors. TS just costs additional tokens and fills up the context window with useless type information; the wasted space could have been used to provide additional code/logical context.</p>
]]></description><pubDate>Wed, 12 Aug 2026 06:56:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=49268715</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49268715</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49268715</guid></item><item><title><![CDATA[New comment by socketcluster in "Go is an ideal language for AI-assisted software engineering"]]></title><description><![CDATA[
<p>Plain JavaScript is the ideal language for AI coding. It's very good with complex architectures.<p>I think partly it's because the training set contains a lot of JS, but also because complex software written in JavaScript must have impeccable architecture in order to exist at all.<p>It's rare to encounter a complex, functioning JavaScript application with bad architecture. I've never met any engineer smart enough to maintain a large spaghetti-code JavaScript project.<p>On the other hand, I've seen horrible TypeScript projects. If it wasn't for the helpful type annotations, no human being would have been able to maintain it.</p>
]]></description><pubDate>Wed, 12 Aug 2026 05:40:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49268199</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49268199</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49268199</guid></item><item><title><![CDATA[New comment by socketcluster in "Retire the Abstractions"]]></title><description><![CDATA[
<p>Many abstractions we encounter in software industry are poor abstractions which are counter-productive. I agree that we should drop those...<p>But we can't drop all abstractions. It's not physically possible. The AI agent is going to break logic up into files... The AI will create/impose an abstraction for each piece of logic whether we like it or not.<p>So saying "drop abstractions" is actually saying "let the AI decide what the abstractions should be" and unfortunately because LLMs are trained on average code, those abstractions are often pretty poor.<p>Coming up with the right abstractions is actually one of the main skills which AI hasn't automated and where the human brings the most value. It affects maintainability directly; including when using AI.<p>I've worked on projects with poor abstractions and ones with good abstractions using AI. The ones with poor abstractions require 10x to 100x more tokens and time to solve problems and implement new features. You're constantly fighting it to prevent it from coming up with nasty hacks and workarounds. Poor abstractions create the need for hacks and workarounds.</p>
]]></description><pubDate>Wed, 12 Aug 2026 03:21:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267482</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49267482</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267482</guid></item><item><title><![CDATA[New comment by socketcluster in "Retire the Abstractions"]]></title><description><![CDATA[
<p>We need abstractions more than ever. The real point is we should retire unnecessary abstractions.<p>A good abstraction is a single edged sword which simplifies the task. A mediocre abstraction is a double-edged sword. A bad abstraction is like a single edged sword with a restrictive handle and the sharp edge is facing towards you.</p>
]]></description><pubDate>Wed, 12 Aug 2026 03:04:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267394</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49267394</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267394</guid></item><item><title><![CDATA[New comment by socketcluster in "Ask HN: What are you working on? (August 2026)"]]></title><description><![CDATA[
<p>I'm working on the backend your AI doesn't have to build <a href="https://saasufy.com/" rel="nofollow">https://saasufy.com/</a><p>For vibe coders.<p>With a focus on:<p>- Security<p>- Analytics<p>- Advanced data sharing scenarios<p>- Realtime updates<p>Claude can be given full access to your control panel and can impersonate any role to exhaustively test all your data models and views. So even a fool can exhaustively prove the security of their application for all data in their system.</p>
]]></description><pubDate>Mon, 10 Aug 2026 08:37:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49240986</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49240986</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49240986</guid></item><item><title><![CDATA[New comment by socketcluster in "What happens if an entire class of workers loses faith in their careers"]]></title><description><![CDATA[
<p>I lost faith in my career long before AI.</p>
]]></description><pubDate>Sat, 08 Aug 2026 15:12:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49222604</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49222604</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49222604</guid></item><item><title><![CDATA[New comment by socketcluster in "From One Seed to a Thousand Leaves – Merkle's Authentication Tree"]]></title><description><![CDATA[
<p>This article describes exactly the quantum-resistant stateful signature scheme I implemented (from scratch) for my blockchain project about 6 years ago; including the Merkle 1979 variant of Lamport OTS. I also constructed a Merkle Signature Key for multiple-reuse in the exact same way described by the article. See <a href="https://capitalisk.com/whitepaper#29-passphrases-and-signature-scheme" rel="nofollow">https://capitalisk.com/whitepaper#29-passphrases-and-signatu...</a>.<p>The article stops exactly where I did and doesn't go further into SPHINCS+ which builds on top of the same primitives to provide statelessness.<p>And the reason I stopped at that was probably the same. There is already a fair amount of complexity involved. I wanted a signature scheme which would be relatively simple to understand and implement. Also, there were no good SPHINCS implementations at the time for my engine/language and I didn't feel confident to implement from scratch.<p>Also, no project at the time (except I think IOTA) had stateful signatures and I liked the idea of being able to change passphrases as it could potentially allow people to sell their wallets (along with associated DEX memberships or delegate spots) to other people.<p>At the time, I was forging as a delegate on a different DPoS blockchain and I was thinking that it would be nice if I could sell my wallet (which would have been worth 5x to 10x my annual block earnings)... Unfortunately, I couldn't do that (no mechanism for it) and I ended up losing that income stream, never having the option to cash out.</p>
]]></description><pubDate>Sat, 08 Aug 2026 14:39:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49222264</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49222264</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49222264</guid></item><item><title><![CDATA[New comment by socketcluster in "Taste Is All That's Left"]]></title><description><![CDATA[
<p>I'm feeling quite confident that AI won't be able to produce quality code in the foreseeable future. Because the bottleneck is not technology, it's people and incentives.<p>Firstly, people don't agree on what good code is (developers who get paid by the hour tend to favor complexity so they think good code is complex code), secondly, AI companies have an incentive to produce more tokens; this works against good architecture since good architecture would cost fewer tokens to maintain. Thirdly, many decision makers tend to conflate complexity with intelligence, hence they are more likely to prefer complex solutions over optimal ones.</p>
]]></description><pubDate>Fri, 07 Aug 2026 10:12:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49208203</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49208203</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49208203</guid></item><item><title><![CDATA[New comment by socketcluster in "Sycophantic AI Decreases Prosocial Intentions and Promotes Dependence (2025)"]]></title><description><![CDATA[
<p>I used these words jokingly and also, I don't mean sycophant in a literal sense. I mean more in an AI context as a kind of config/slider you can dial up or down to make it more collaborative or combative.<p>If I'm knowledgeable in a niche over which there is no mainstream consensus or it's disorganized, and I want to reason more about this topic, I need the AI in the rabbit hole with me. I don't need it to question the existence of the rabbit hole I'm in. Otherwise all of its arguments sound like gaslighting; asking me to disbelieve my eyes and decades of experience about basic ideas which I've already researched many times and proven not to work (at least with high confidence).<p>For me this happens with some niches of software engineering and architecture and I have lots of physical proof of working, secure, maintainable software to back up my position.<p>Also, when I say that "most of my contrarian ideas are correct" it's with the caveat that I don't tend to adopt or hold onto contrarian ideas that are easily proven to be incorrect. I'm referring to the kinds of niche ideas which most non-experts would not feel confident to make strong arguments about but AI will.</p>
]]></description><pubDate>Thu, 06 Aug 2026 22:02:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=49203227</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49203227</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49203227</guid></item><item><title><![CDATA[New comment by socketcluster in "Taste Is All That's Left"]]></title><description><![CDATA[
<p>In software development, good taste translates to readability, succinctness and maintainability of the code. It also translates to intuitiveness, reliability, security, performance, scalability and utility of the software.<p>All this doesn't necessarily translate to sales though. Because, to evaluate those things requires attention, trust, time and effort.<p>This is a significant barrier because a lot of software will appear to meet all of these superficially.<p>After 1 day of usage, a piece of software may appear to be intuitive, reliable, secure, performant and useful... But then after some time (sometimes a whole week or longer) you run into a critical scenario and discover that it cannot be solved with that software... Or performance drops off sharply after you created the 1000th record in the software... Or a hacker takes months to find that one endpoint which allows full remote code execution.<p>Even in an optimistic scenario, 1 week is a long time to evaluate a piece of software. I've encountered software which took 6 months and large teams of people to realize that it wasn't suitable. That's how long it took to hit the critical limits. It's a very long evaluation loop.<p>So you cannot judge new software efficiently by just looking at it. Even industry consensus is problematic if the software is very new and complex... Plenty of trends have fallen off a cliff in the past. You need to understand who is behind the software... And even that's not so easy; social proof can be misleading when it comes to deep technical ideas. The people who are good at social networking aren't necessarily good with tech.<p>I think AI slop code is going to be a much bigger problem than people anticipate. And the irony of it is that the solutions already exist... What doesn't exist is the mechanism to identify those solutions. But even the mindset needs to be corrected first.</p>
]]></description><pubDate>Thu, 06 Aug 2026 21:49:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49203060</link><dc:creator>socketcluster</dc:creator><comments>https://news.ycombinator.com/item?id=49203060</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49203060</guid></item></channel></rss>